Manage user roles
Manage Cortex Cloud user roles and define permissions for tenant access.
Prerequisite
Managing user roles in Cortex Cloud Access Management requires View/Edit RBAC permissions for Access Management (under Configurations). Account Admin and Instance Administrator roles are granted this permission by default. For more information, see Predefined user roles in Set up users, groups, and roles.
Review the following topics:
Set up users and roles
User group management
Assign user roles and groups
Manage user roles and access management
Manage user roles that are assigned to Cortex Cloud users, user groups, or API keys. User roles enable you to define the type of access and actions a user can perform.
You can only set dataset access permissions from a user role in Cortex Cloud Access Management for the tenant. When creating user roles from the Cortex Gateway, these settings are disabled. By default, dataset access management is disabled, and users have access to all datasets. If you enable dataset access management, you must configure access permissions for each dataset type, and for each user role. When a dataset component is enabled for a particular role, the Issues and Cases pages include information about datasets.
Be aware that even with scoped access to dataset rows applied, users can still indirectly access unauthorized dataset rows through dataset views and correlation rules. You can prevent this by ensuring that users don't have access to these dataset views and are unable to write correlation rules based on these datasets by enabling dataset access management for the relevant user roles, and limiting access to the applicable datasets. You may also want to consider not allowing these dataset-scoped users to write correlation rules, which we recommend as a best practice. For more information on row-level scoping, see Manage user scope.
Last updated
Was this helpful?
